Domains

by get-convex6ca54f6e2e75Apache-2.0Listed Oct 8, 2026Updated Oct 8, 2026

Wire a domain the user ALREADY OWNS (GoDaddy/Namecheap/Cloudflare/…) to their Convex app: exact DNS records, custom-domain attachment, auth-origin rebind. TRIGGER when the user owns a domain and wants it pointing at their app ('point my domain at this', 'use my own domain', 'set up example.com'). Never asks for registrar credentials.

Instructions onlyDevOps & Cloud
AI-generated overview

Guides attaching a user-owned domain to a Convex app with exact DNS records, domain attachment and auth-origin rebinding.

What it does
This skill walks through pointing a domain the user already owns at a Convex app. It identifies the target host, supplies the exact CNAME or apex A/ALIAS record plus the TXT verification record, attaches the custom domain on Convex, and rebinds auth origin environment variables when the app uses passkeys or OAuth. It finishes by verifying HTTPS serving and any apex-to-www redirect.
When to use it
Use it when a user owns a domain and wants it pointed at their Convex app, such as requests to use their own domain or set up example.com. It fits custom-domain attachment and post-move auth-origin fixes.
Requirements
A Convex app and deployment access (dashboard or CLI, e.g. npx convex env get CONVEX_SITE_URL), plus the user's registrar access to create DNS records. No registrar credentials are requested. Instructions only; no scripts.

Custom domain with your own provider (/domains)

Point a domain the user already owns at their Convex app. No purchase, no registrar credentials — you give the user the exact records to create themselves.

Procedure

  1. Identify the target: the published site host (for static hosting) or the deployment's HTTP actions URL (npx convex env get CONVEX_SITE_URL or the dashboard).
  2. Give the exact DNS records to create at THEIR registrar: the CNAME (or A/ALIAS at the apex) plus the TXT verification record — concrete host/value strings, not placeholders.
  3. Attach the custom domain on Convex (dashboard → deployment → Custom Domains, or the CLI) and wait for verification. DNS propagation can take minutes to hours — tell the user, don't poll forever.
  4. If the app uses auth (passkeys/OAuth), rebind the auth origin (SITE_URL / RP_ID / ORIGIN env vars) to the new domain and re-deploy — otherwise sign-in breaks on the new domain.
  5. Verify: the domain serves the app over HTTPS, including the apex → www redirect if configured.

Rules

  • Never ask for registrar credentials — the user creates the records.
  • Always include the TXT verification record, not just the CNAME.
  • Rebinding the domain changes the auth origin — re-deploy after, or sign-in breaks.

Source and attribution

Source:get-convex/convex-backend-skillinskills/domainsat commit6ca54f6

License: Apache-2.0

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal